What I do is ship my log files off box (I'm using Splunk) and then filter them there. The danger in what your asking for is to have a set of log files for each service and so each time you publish one it would consume more of your /opt partition which would eventually fill and cause your gateway(s) to go down.